Skip to content

Conversation

@jmwiese
Copy link
Contributor

@jmwiese jmwiese commented Dec 13, 2024

What? Why?

The previous version of messageformat (which is quite old) uses underscore which has a security vulnerability

https://github.com/bigcommerce/storefront-renderer-2/security/dependabot/4

This updates to the closest version which doesnt not have underscore

How was it tested?

Tested locally

Before:
Screenshot 2024-12-13 at 9 39 59 AM

After:
Screenshot 2024-12-13 at 9 39 37 AM


cc @bigcommerce/storefront-team

@jmwiese jmwiese changed the title Update messageformat dependency fix(storefront): STRF-12688 Update messageformat dependency Dec 13, 2024
@jmwiese jmwiese force-pushed the STRF-12688 branch 5 times, most recently from 5d8807f to 8b1abe1 Compare December 16, 2024 16:30
@jmwiese jmwiese merged commit f27c8fe into master Dec 26, 2024
3 checks passed
@github-actions
Copy link
Contributor

🎉 This PR is included in version 5.0.3 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants